Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
simonfili
New Contributor

High level architecture questions (pre-sale)

Hi All,

 

I'm simply trying to see which Fortinet product I can use to 

1) Aggregate / load balance 2-3 wan link.  At a minimum 2 fiber from 2 source.  I would like an LTE backup for a 3rd link.  This is for a highly unstable environment

2) Having a firewall for protecting the network, connecting remotes sites with VPN links, all controlled by policies linked to AD groups.

 

Can I use one fortigate product for that or I need 2?

 

Thanks

1 Solution
ede_pfau
SuperUser
SuperUser

"aggregate" or "load balance"?

With 2 ISPs, you cannot use a FGT to aggregate the WAN lines for higher throughput and redundancy. You would have to use a device which combines data streams on Layer 2. This would require a second identical device on the other side to de-interlace.

LB, sure, use SD-WAN (formerly WLLB, formerly...). This combines load balancing with monitoring, esp. remote monitoring, covering not only device failure and link failure but also route failure some hops further up.

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
3 REPLIES 3
ede_pfau
SuperUser
SuperUser

"aggregate" or "load balance"?

With 2 ISPs, you cannot use a FGT to aggregate the WAN lines for higher throughput and redundancy. You would have to use a device which combines data streams on Layer 2. This would require a second identical device on the other side to de-interlace.

LB, sure, use SD-WAN (formerly WLLB, formerly...). This combines load balancing with monitoring, esp. remote monitoring, covering not only device failure and link failure but also route failure some hops further up.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
simonfili

Thanks Ede for the info.

 

I was looking at this type of product: https://www.mushroomnetworks.com/truffle/

and was wondering if fortigate could do the same.  

 

From your comments, I could do load balance but not aggregate (bonding) which the truffle can do.

 

I have two "slow" fiber link on the project (2-5 Mbps), thus the need to aggregate.

 

For LB, SD-Wan can be used with a Fortigate 200E ?

 

Thanks

ede_pfau

Yes, SD-WAN is a feature of FortiOS v5.4 and (better) v5.6, independent of the hardware. It combines zones, routing, dead gateway detecting via pingservers in a neat way.

Bonding OTOH is not in the feature set of a Fortigate, but might be in other Fortinet products (which I do not know enough to name). Maybe check out FortiADC.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors